Request for a Surveillance Tower: Evasive Tactics in Cyber Defense Exercises

Young-Jun Maeng, Mauno Pihelgas
{"title":"Request for a Surveillance Tower: Evasive Tactics in Cyber Defense Exercises","authors":"Young-Jun Maeng, Mauno Pihelgas","doi":"10.23919/CyCon58705.2023.10182014","DOIUrl":null,"url":null,"abstract":"The cyber defense exercise (CDX) is an emerging live-fire exercise that enables diverse teams with different roles to train in one game. To evaluate the cyber defense capabilities of the training audience, organizers prepare various scores using different scoring methods ranging from technical to non-technical. The technical scores in Locked Shields, for example, consist of an availability check, a usability check, the success of the red team (RT) attack, and forensics.Immersed in scores due to excessive competition, a blue team (BT) may unnecessarily focus on the scoring process, aiming to perform evasive tactics (ET), which boosts scores unfairly by abusing the weaknesses of the scoring system. ET has occurred in various forms in existing CDXs, and similar cases have been found in the recent iteration of CDXs, meaning that ET is becoming BT’s selectable strategy.Such a phenomenon is undesirable since it will reduce the reliability of the evaluation and the effectiveness of the training. In this paper, we provide an overview of an availability check and examine ET that appeared in both the availability check and RT’s evidence-obtaining process, followed by several mitigations to them. We also discuss evidence and usability issues of ET in CDX and conclude by emphasizing the importance of supporting the green team (GT) in researching and implementing a robust scoring system.","PeriodicalId":391972,"journal":{"name":"2023 15th International Conference on Cyber Conflict: Meeting Reality (CyCon)","volume":"25 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 15th International Conference on Cyber Conflict: Meeting Reality (CyCon)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/CyCon58705.2023.10182014","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The cyber defense exercise (CDX) is an emerging live-fire exercise that enables diverse teams with different roles to train in one game. To evaluate the cyber defense capabilities of the training audience, organizers prepare various scores using different scoring methods ranging from technical to non-technical. The technical scores in Locked Shields, for example, consist of an availability check, a usability check, the success of the red team (RT) attack, and forensics.Immersed in scores due to excessive competition, a blue team (BT) may unnecessarily focus on the scoring process, aiming to perform evasive tactics (ET), which boosts scores unfairly by abusing the weaknesses of the scoring system. ET has occurred in various forms in existing CDXs, and similar cases have been found in the recent iteration of CDXs, meaning that ET is becoming BT’s selectable strategy.Such a phenomenon is undesirable since it will reduce the reliability of the evaluation and the effectiveness of the training. In this paper, we provide an overview of an availability check and examine ET that appeared in both the availability check and RT’s evidence-obtaining process, followed by several mitigations to them. We also discuss evidence and usability issues of ET in CDX and conclude by emphasizing the importance of supporting the green team (GT) in researching and implementing a robust scoring system.
对监视塔的请求:网络防御演习中的规避战术
网络防御演习(CDX)是一种新兴的实弹演习,可以让不同角色的不同团队在一个游戏中进行训练。为了评估培训观众的网络防御能力,组织者使用从技术到非技术的不同评分方法准备了各种分数。例如,锁定盾牌中的技术分数由可用性检查、可用性检查、红队(RT)攻击的成功和取证组成。蓝队(BT)因过度竞争而沉迷于分数,有可能在不必要的情况下专注于得分过程,利用分数制度的弱点,实施不公平的得分战术(ET)。在现有的cdx中,ET以各种形式出现,在最近的cdx迭代中也发现了类似的情况,这意味着ET正在成为英国电信的可选策略。这种现象是不可取的,因为它会降低评估的可靠性和培训的有效性。在本文中,我们概述了可用性检查,并检查了可用性检查和RT的证据获取过程中出现的ET,然后对它们进行了一些缓解。我们还讨论了CDX中ET的证据和可用性问题,最后强调了支持绿色团队(GT)研究和实施稳健评分系统的重要性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信